Bug 1173555 (CVE-2014-7824)
| Summary: | CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636 | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> | ||||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||
| Status: | CLOSED NOTABUG | QA Contact: | |||||||
| Severity: | low | Docs Contact: | |||||||
| Priority: | low | ||||||||
| Version: | unspecified | CC: | amigadave, dking, drizt72, erik-fedora, jrusnack, lpoetter, slawomir, walters | ||||||
| Target Milestone: | --- | Keywords: | Security | ||||||
| Target Release: | --- | ||||||||
| Hardware: | All | ||||||||
| OS: | Linux | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | dbus 1.6.26, dbus 1.8.10, dbus 1.9.2 | Doc Type: | Bug Fix | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2014-12-12 23:32:21 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Bug Depends On: | 1173556, 1173557, 1173558 | ||||||||
| Bug Blocks: | 1140534, 1160627 | ||||||||
| Attachments: |
|
||||||||
|
Description
Vasyl Kaigorodov
2014-12-12 12:12:07 UTC
Created dbus tracking bugs for this issue: Affects: fedora-all [bug 1173556] Created mingw-dbus tracking bugs for this issue: Affects: fedora-all [bug 1173557] Affects: epel-7 [bug 1173558] Created attachment 967617 [details]
0001-DBusSystemLogSeverity-add-DBUS_SYSTEM_LOG_WARNING.patch
Created attachment 967618 [details]
0002-Set-fd-rlimit-to-64k-for-the-system-dbus-daemon.patch
Original report to oss-security: http://www.openwall.com/lists/oss-security/2014/11/10/2 Note that CVE-2014-3636 (bug #1140525) was not previously corrected by any errata. As no prior Red Hat Enterprise Linux release contains the incorrect fix, they are not affected by this particular CVE. See bug #1140525 for details. dbus-1.6.28-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. dbus-1.8.12-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. dbus-1.6.28-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. |